From e13b8a973eb8be8252a21feb066bd1853e9002a0 Mon Sep 17 00:00:00 2001 From: Vincas Dargis Date: Sat, 26 Jan 2019 17:26:05 +0200 Subject: [PATCH] fix(apparmor): Fix .local/share/qTox/ access Capturing desktop screenshot produces this DENIED messages: ``` type=AVC msg=audit(1548516170.837:3146): apparmor="DENIED" operation="mkdir" profile="qtox" name="/home/vincas/.local/share/qTox/" pid=12605 comm="qtox" requested_mask="c" denied_mask="c" fsuid=1000 ouid= 1000 ``` Add rule to allow writing to .local/share/qTox/ --- security/apparmor/2.12.1/usr.bin.qtox | 1 + security/apparmor/2.13.2/usr.bin.qtox | 1 + 2 files changed, 2 insertions(+) diff --git a/security/apparmor/2.12.1/usr.bin.qtox b/security/apparmor/2.12.1/usr.bin.qtox index 0ea050fd3..675f36400 100644 --- a/security/apparmor/2.12.1/usr.bin.qtox +++ b/security/apparmor/2.12.1/usr.bin.qtox @@ -183,6 +183,7 @@ profile qtox /usr{,/local}/bin/qtox { owner @{HOME}/.config/qToxrc.lock rwk, owner @{HOME}/.config/tox/** l -> @{HOME}/.config/tox/**, # QSaveFile? owner @{HOME}/.config/tox/{,**} rwk, + owner @{HOME}/.local/share/qTox/{,**} rw, owner @{HOME}/.local/share/user-places.xbel r, # file dialog owner @{PROC}/@{pid}/cmdline r, diff --git a/security/apparmor/2.13.2/usr.bin.qtox b/security/apparmor/2.13.2/usr.bin.qtox index 27d344ca5..7996d2dae 100644 --- a/security/apparmor/2.13.2/usr.bin.qtox +++ b/security/apparmor/2.13.2/usr.bin.qtox @@ -189,6 +189,7 @@ profile qtox /usr{,/local}/bin/qtox { owner @{HOME}/.config/qToxrc.lock rwk, owner @{HOME}/.config/tox/** l -> @{HOME}/.config/tox/**, # QSaveFile? owner @{HOME}/.config/tox/{,**} rwk, + owner @{HOME}/.local/share/qTox/{,**} rw, owner @{HOME}/.local/share/user-places.xbel r, # file dialog owner @{PROC}/@{pid}/cmdline r,